PT-2025-37502 · Linux+4 · Linux Kernel+4

Published

2022-11-28

·

Updated

2025-11-12

·

CVE-2022-50248

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a vulnerability in the iwlwifi MVM subsystem that can lead to a double free on the transmit path. This issue can cause kernel crashes, lockups, and KASAN errors, particularly with ax210 firmware. The vulnerability occurs when the iwl mvm tx skb sta function returns a non-zero value, leading to the freeing of an skb, which may also be freed in an error case when building a TSO skb buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Double Free

Weakness Enumeration

Related Identifiers

BDU:2026-06070
CVE-2022-50248
SUSE-SU-2025:03613-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4004-1
SUSE-SU-2025:4016-1
SUSE-SU-2025:4064-1

Affected Products

Astra Linux
Linux Kernel
Suse
Ax210 Firmware
Iwlwifi